This Privacy Policy describes how Batuhan Kaçmaz (“we”, “us”, “our”) collects, uses, and shares personal information when you use the Heron Tai Chi mobile application (the “App”). It is written for this App specifically and is not a generic template.
We comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Turkish Personal Data Protection Law (KVKK, Law No. 6698), and applicable App Store privacy requirements.
1. Quick Summary
| Question | Short answer |
|---|---|
| Do I need to create an account? | No. The App signs you in anonymously. We never ask for your name, email address, or phone number. |
| What do you actually store? | Your answers to the setup questions (including wellness answers you choose to give), your practice history, any feedback you write, and whether you have a subscription. |
| Do you collect health information? | Yes — but only what you tell us yourself during setup, such as your age, where you feel aches, and how three gentle movement checks felt. We ask for your explicit consent first. See Section 3.2. |
| Do you sell my personal information? | No. |
| Do you “share” my information for cross-context behavioral advertising (CCPA/CPRA)? | No. |
| Do you track me or use advertising identifiers? | No. The App contains no advertising, no analytics SDK, and no crash-reporting SDK. |
| Do you know my location? | No. We never request or store location data. |
| Where is my data processed? | Your practice data is stored in Frankfurt, Germany (EU). Subscription records (RevenueCat) and payments (Apple) are processed in the United States. |
| How do I delete my data? | Email support@wearebasestudio.com — we delete within 30 days. See Section 8.4. |
| Who is the data controller? | Batuhan Kaçmaz, Türkiye — support@wearebasestudio.com |
The rest of this document explains each of these points in detail.
2. Who We Are (Data Controller)
The data controller (KVKK: Veri Sorumlusu) for personal information processed by the App is:
- Name: Batuhan Kaçmaz
- Country: Türkiye
- Privacy contact: support@wearebasestudio.com
- Support contact: support@wearebasestudio.com
We are an independent developer, not a large organisation. We do not have a Data Protection Officer (DPO) under GDPR Article 37, as our processing operations do not require one. For any privacy question, contact us directly at the email above.
3. What Information We Collect
The App has no sign-up screen. You are never asked for your name, email address, phone number, or password. Instead, the App creates an anonymous account for you automatically so that your practice progress can be saved and restored.
3.1 Your Anonymous Account
When you first open the App, we create:
- A random device identifier — a randomly generated UUID stored in your device’s iOS Keychain. It contains nothing about you or your device hardware. Its only purpose is to recognise your existing progress if your session expires or you reinstall the App.
- An anonymous user ID — a random identifier issued by our sign-in provider (Supabase) and linked to the device identifier above.
Neither identifier is derived from your Apple ID, your device serial number, your advertising identifier (IDFA), or any other permanent hardware ID. We cannot use them to learn who you are.
For technical reasons, our sign-in provider requires every account to have an email address on file. For anonymous users we generate a synthetic placeholder address internally from the random identifiers described above. It is not a working mailbox, it is never used to contact you, and it contains no personal information about you.
3.2 Setup Answers, Including Health-Related Information
Before your first practice, the App asks a short series of questions so it can build a suitable 28-day plan. You choose what to answer, and you may skip questions. These answers are stored on our servers so your plan survives a reinstall:
- Your age (you set it with a slider; the default is 55)
- Your goal — for example feeling calmer, better balance, moving more freely, or easing aches and pain
- Areas where you feel aches or pain — knees, hips, lower back, shoulders, neck
- Your sleep quality and when you feel most energetic
- Your previous experience with Tai Chi
- How three gentle movement checks felt — holding your arms up, turning your neck, and standing balance
- Your practice preferences — daily minutes goal, preferred time of day, motivation, and what usually gets in the way
- Your time zone, so reminders and daily progress land on the right day
This is health-related information. Under GDPR Article 9 and KVKK Madde 6, details about aches and pain, sleep, and physical mobility are treated as a special category of personal data that deserves extra protection. We therefore:
- Ask for your explicit consent before processing it (GDPR Article 9(2)(a), together with Article 6(1)(a); KVKK Madde 6 açık rıza). Continuing through the setup questions and saving your plan is that consent.
- Use it for one purpose only: choosing which movements and which pace to show you, and which to leave out. For example, if you report knee discomfort, the plan favours lower-impact variations.
- Never use it for advertising, profiling, scoring, insurance, employment, or any decision that produces a legal or similarly significant effect on you.
- Never share it with advertisers, data brokers, insurers, or any third party other than the infrastructure providers listed in Section 5, who store it on our behalf and may not use it for their own purposes.
You can withdraw this consent at any time — see Section 8.4.
3.3 Your Practice Activity
As you use the App we record, on our servers:
- Which practice sessions you completed, on which day of your programme, and which movement was practised
- How long each session lasted, and when it was completed
- Which programme track you are following (for example beginner or gentle foundations)
- The date you were last active
This is what produces your progress view, your calendar, and your totals.
3.4 Feedback You Write
If you rate a movement or answer the short question at the end of a session, we store your rating, the preset reason you picked (if any), and any free-text note you type. Please do not include your name, contact details, or medical details in free-text notes — they are not needed, and we would rather not hold them.
3.5 Subscription Information
If you purchase a subscription or the lifetime unlock, we store whether you have an active entitlement and which tier it is. Payment itself is handled entirely by Apple. See Section 3.6.
3.6 What Apple and RevenueCat Handle
- We never see your payment details. Your card, Apple ID, and billing address stay with Apple. We receive only a confirmation that a purchase is valid.
- RevenueCat, our subscription-records provider, receives your App Store transaction receipt, the product purchased, the subscription status (trial, active, expired, cancelled), your anonymous user ID, and technical metadata that Apple attaches to the transaction such as device model, OS version, country of the store, and the IP address of the request (used by RevenueCat for fraud prevention).
Source: RevenueCat Apple App Privacy documentation.
3.7 What We Do Not Collect
To be explicit, the App does not collect, request, or store:
- Your name, email address, phone number, or postal address
- Precise or approximate location data
- Advertising identifiers (IDFA), and we do not ask for App Tracking Transparency permission because we do not track you
- Apple Health / HealthKit data — the App does not connect to HealthKit
- Contacts, calendars, photos, microphone audio, or camera images
- Biometric identifiers, racial or ethnic origin, religious or political beliefs, or sexual orientation
- Analytics or crash-reporting data. The App contains no analytics SDK and no crash-reporting SDK. We do not use Google Analytics, Firebase, Crashlytics, Mixpanel, Amplitude, or any comparable service.
3.8 Notifications
If you allow notifications, practice reminders are scheduled locally on your device by iOS. We do not operate a push-notification server and we do not collect a push token. You can turn reminders off at any time in iOS Settings.
4. How We Use Information (Purposes and Legal Bases)
Under GDPR Article 6 (and Article 9 where health-related data is involved), we rely on the following legal bases. The equivalent CCPA/CPRA “business purposes” are listed in the same row.
| Purpose | Data used | GDPR legal basis | CCPA/CPRA business purpose |
|---|---|---|---|
| Create and restore your anonymous account so your progress is not lost | Device identifier, anonymous user ID | Contract (Art. 6(1)(b)) | Performing services |
| Build and adapt your 28-day practice plan to your body and goals | Setup answers, including health-related answers | Explicit consent (Art. 9(2)(a) with Art. 6(1)(a)) — you may withdraw at any time | Performing services |
| Show your progress, streaks, calendar, and totals | Practice session history | Contract (Art. 6(1)(b)) | Performing services |
| Unlock paid content and restore purchases | Subscription status, anonymous user ID, App Store receipt | Contract (Art. 6(1)(b)) | Performing services |
| Prevent payment fraud and abuse of free trials | App Store receipt, transaction metadata | Legitimate interest (Art. 6(1)(f)) — protecting against fraud | Auditing / security |
| Improve the lessons and fix confusing instructions | Movement and session feedback, including free-text notes | Consent (Art. 6(1)(a)) — you choose whether to send feedback | Internal research |
| Respond to your support requests | The email you send us and its contents | Legitimate interest (Art. 6(1)(f)) | Customer service |
We do not use your data for advertising profiling, automated decision-making producing legal or similarly significant effects (GDPR Article 22), or sale to third parties.
5. Who Receives Your Data (Sub-processors)
We share specific, limited information with the sub-processors below. Each is bound by a Data Processing Agreement to process data only on our instructions, with safeguards equal to or greater than this policy. We do not share your personal information with any other third party, and we do not sell it to anyone.
5.1 Supabase, Inc.
- Role: Anonymous sign-in, authentication tokens, and the PostgreSQL database that stores your plan, setup answers, practice history, and feedback.
- Data shared: Everything described in Sections 3.1 to 3.5 — this is our primary data store.
- Location: The database is hosted in Frankfurt, Germany (European Union). Supabase, Inc. is headquartered in the United States and may access data from there for support and maintenance.
- Safeguards: Standard Contractual Clauses (SCCs) for transfers outside the EEA; SOC 2 Type II compliance; encryption in transit and at rest.
- Their privacy policy: https://supabase.com/privacy
- Their DPA: https://supabase.com/legal/dpa
5.2 RevenueCat, Inc.
- Role: Subscription state management, App Store receipt validation, fraud prevention, and restoring purchases across your devices.
- Data shared: Anonymous user ID, App Store receipt, product and subscription status, and transaction metadata (device model, OS version, store country, IP address). No health-related data and no practice history is ever sent to RevenueCat.
- Location: United States.
- Safeguards: Standard Contractual Clauses (SCCs) for EU/UK transfers; SOC 2 Type II compliance.
- Their privacy policy: https://www.revenuecat.com/privacy
- Their DPA: https://www.revenuecat.com/dpa/
5.3 Railway Corp.
- Role: Hosting for our application server, which sits between the App and the database. It handles your requests as they pass through and does not keep its own copy of your practice data.
- Data shared: Whatever your device sends to or receives from our server, transiently, plus standard server operational logs.
- Location: Railway Corp. is based in the United States.
- Safeguards: Standard Contractual Clauses (SCCs) for EU/UK transfers; encryption in transit and at rest.
- Their privacy policy: https://railway.com/legal/privacy
- Their DPA: https://railway.com/legal/dpa
5.4 Apple Inc.
Apple processes your payment, hosts the App, manages your subscription, and provides the App Store. We never receive your payment details. Apple may also provide us with aggregate, non-identifying App Store statistics such as download and subscription counts. Apple’s practices are governed by Apple’s own privacy policy: https://www.apple.com/legal/privacy/.
6. International Data Transfers
Your practice data — including the health-related setup answers described in Section 3.2 — is stored in Frankfurt, Germany, inside the European Union. It is not transferred to the United States.
Subscription and payment information is different: it is processed in the United States by RevenueCat and Apple, because that is where those services operate.
Our application server is hosted by Railway, a United States company. Your requests pass through it on their way to and from the database, so data may be processed outside the EU in transit, even though it comes to rest in Frankfurt.
For users in the European Economic Area, the United Kingdom, Switzerland, and Türkiye, any transfer outside your region is protected by:
- Standard Contractual Clauses (SCCs) approved by the European Commission, in place with each sub-processor.
- EU-US Data Privacy Framework certification, where the recipient is certified.
- Additional technical and organisational measures — encryption in transit (TLS 1.2+) and at rest, and restricted administrative access.
For transfers from Türkiye, we rely on your explicit consent (açık rıza) under KVKK Madde 9 together with the contractual safeguards above, pending an adequacy decision for the recipient countries.
7. How Long We Keep Your Data (Retention)
| Data category | Retention |
|---|---|
| Anonymous account and device identifier | Until you request deletion, or after 24 months of complete inactivity, whichever comes first |
| Setup answers, including health-related answers | Until you request deletion, withdraw consent, or the 24-month inactivity period above elapses |
| Practice session history | Same as your account — it is the basis of your progress view |
| Movement and session feedback, including free-text notes | 24 months, then deleted |
| Subscription and purchase records | As long as your subscription is active, plus up to 10 years where Turkish tax and commercial law requires us to keep transaction records |
| Server operational logs | 30 days, then automatically deleted |
| Support email correspondence | 24 months from our last reply, then deleted |
You can request earlier deletion at any time — see Section 8.4.
8. Your Rights
8.1 Rights under GDPR (EU/UK/EEA users)
You have the following rights:
- Right of access to the personal data we hold about you (Article 15)
- Right to rectification of inaccurate or incomplete data (Article 16)
- Right to erasure — also called the “right to be forgotten” (Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability in a machine-readable format (Article 20)
- Right to object to processing based on our legitimate interest (Article 21)
- Right to withdraw consent at any time, where processing is based on consent — including the explicit consent for health-related data described in Section 3.2 (Article 7(3)). Withdrawing consent does not affect the lawfulness of processing carried out before you withdrew it.
- Right to lodge a complaint with your local data protection supervisory authority
To exercise these rights, email support@wearebasestudio.com. We respond within 30 days.
8.2 Rights under CCPA/CPRA (California residents)
If you are a California resident, you have the following rights:
- Right to know what personal information we have collected, used, disclosed, and shared in the past 12 months (§1798.110, .115)
- Right to delete your personal information (§1798.105)
- Right to correct inaccurate personal information (§1798.106)
- Right to opt-out of the sale or sharing of personal information (we do not sell or share — see below)
- Right to limit the use and disclosure of sensitive personal information (§1798.121). The health-related answers described in Section 3.2 are sensitive personal information. We use them solely to provide the service you asked for — building your practice plan — which is a permitted purpose. We never use them to infer characteristics about you.
- Right to non-discrimination for exercising any of these rights (§1798.125). We will not degrade the App or change your price because you exercised a privacy right.
We do not sell or share your personal information as those terms are defined in the CCPA/CPRA. We do not engage in cross-context behavioral advertising. You may still send a “Do Not Sell or Share” request to confirm this in writing: support@wearebasestudio.com.
You may use an authorized agent to submit requests on your behalf, subject to verification of authority.
This Privacy Policy is reviewed and updated at least every 12 months, as required by the CCPA.
8.3 KVKK rights (Türkiye)
KVKK Madde 11 kapsamında aşağıdaki haklara sahipsiniz (your rights under Article 11 of the Turkish Personal Data Protection Law):
- Kişisel verilerinizin işlenip işlenmediğini öğrenme.
- İşlenmişse, buna ilişkin bilgi talep etme.
- İşlenme amacını ve amacına uygun kullanılıp kullanılmadığını öğrenme.
- Yurt içinde veya yurt dışında aktarıldığı üçüncü kişileri bilme.
- Eksik veya yanlış işlenmiş olması hâlinde düzeltilmesini isteme.
- KVKK’nın 7. maddesinde öngörülen şartlar çerçevesinde silinmesini veya yok edilmesini isteme.
- (5) ve (6) bentleri uyarınca yapılan işlemlerin, aktarıldığı üçüncü kişilere bildirilmesini isteme.
- Otomatik sistemler ile analiz edilmesi suretiyle kişiniz aleyhine bir sonucun ortaya çıkmasına itiraz etme.
- Hukuka aykırı işlenmesi sebebiyle zarara uğramanız hâlinde zararın giderilmesini talep etme.
This document also serves as our Aydınlatma Metni (disclosure notice) under KVKK Madde 10. Sections 2 through 7 identify the data controller, the categories of data processed, the purposes of processing, the recipients, the legal grounds, and the transfer safeguards required by that article. Health-related data described in Section 3.2 is özel nitelikli kişisel veri under Madde 6 and is processed only with your explicit consent (açık rıza).
To exercise your rights, write to support@wearebasestudio.com.
8.4 How to Delete Your Data or Withdraw Consent
Because your account is anonymous, we cannot identify you from your name or email — we need the identifier the App holds.
- Email support@wearebasestudio.com with the subject “Delete my data”.
- We will reply with a short instruction for retrieving your account identifier from the App, so that we delete the right account and no one else’s.
- Once confirmed, we delete your account, setup answers, practice history, and feedback within 30 days. Deletion is permanent and cannot be undone.
Deleting the App from your device does not by itself delete data from our servers, because your progress is intentionally preserved so it can be restored if you reinstall. Use the process above if you want it erased.
Please note: deleting your data does not cancel your subscription, because Apple — not us — manages billing. Cancel your subscription in iOS Settings → your name → Subscriptions.
9. Security
We protect your data using:
- Transport encryption (HTTPS/TLS 1.2+) for all traffic between the App, our server, and our sub-processors
- At-rest encryption by all sub-processors (Supabase, RevenueCat, Railway, Apple)
- Short-lived access tokens for the App, refreshed automatically, rather than long-lived credentials stored on the device
- Device identifier stored in the iOS Keychain, which is hardware-encrypted by the operating system
- Access controls limiting administrative database access to the developer only
No method of transmission over the internet or electronic storage is 100% secure. We commit to notify the competent supervisory authority within 72 hours, and affected users without undue delay, of any data breach affecting their personal information, in line with GDPR Articles 33 and 34 and the corresponding KVKK notification duty.
10. Children
Heron Tai Chi is designed for adults, and in particular for practitioners aged 60 and over. It is not directed to children under the age of 13 (or under 16 in the EEA), and it is not listed in the App Store Kids Category. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact support@wearebasestudio.com and we will delete it promptly.
We do not knowingly sell or share the personal information of minors under 16 (CCPA opt-in requirement).
11. Changes to This Policy
We may update this Privacy Policy when we change the way the App works, add or remove a sub-processor, or when laws change. The “Last updated” date at the top reflects the most recent revision. Material changes — in particular any change to what we collect or who receives it — will be communicated in the App before they take effect, and where the change concerns health-related data we will ask for your consent again. The current version is always available at: https://herontaichi.com/privacy.
12. Contact Us
For any privacy question, request to exercise your rights, or breach notification:
- Email: support@wearebasestudio.com
- Subject line examples: “GDPR Access Request”, “CCPA Deletion Request”, “Delete my data”, “Privacy Question”
- KVKK başvuruları için: support@wearebasestudio.com
We aim to respond within 5 business days, and in any event within 30 days as required by GDPR and CCPA.
Last updated: 2026-07-20. Heron Tai Chi is published by Batuhan Kaçmaz, Türkiye. This policy is written to satisfy Apple App Store Review Guideline 5.1.1(i), GDPR Articles 13–14, CCPA/CPRA, and KVKK Madde 10.